Cyber Resilience

CWE · MITRE source

CWE-908Use of Uninitialized Resource

Abstraction: Base · CVEs in our corpus: 837

The product uses or accesses a resource that has not been initialized.

When a resource has not been properly initialized, the product may behave unexpectedly. This may lead to a crash or invalid memory access, but the consequences vary depending on the type of resource and how it is used within the product.

Last updated: 21 August 2026 00:24 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
  • SA-11 Developer Testing and Evaluation
  • SA-8 Security and Privacy Engineering Principles
  • SA-15 Development Process, Standards, and Tools
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2023-24941 9.99.80.94682023-05-09
CVE-2008-0081 9.59.80.57912008-01-16
CVE-2012-1891 8.89.80.29412012-07-10
CVE-2021-40418 8.59.80.17942021-12-22
CVE-2025-5777 KEV 8.57.50.99962025-06-17
CVE-2008-3475 8.38.80.39862008-10-15
CVE-2019-9641 8.29.80.09402019-03-09
CVE-2025-50165 8.29.80.09522025-08-12
CVE-2019-0006 8.09.80.05262019-01-15
CVE-2015-8390 7.99.80.04622015-12-02
CVE-2018-5095 7.99.80.04212018-06-11
CVE-2018-14551 7.99.80.04032018-07-23
CVE-2019-12730 7.89.80.03032019-06-04
CVE-2019-7321 7.89.80.03212019-06-13
CVE-2019-5067 7.89.80.03412019-09-18
CVE-2019-15900 7.79.80.02112019-10-18
CVE-2020-24753 7.79.80.02642020-09-17
CVE-2018-25014 7.79.80.02232021-05-21
CVE-2007-1751 7.60.00.60842007-06-12
CVE-2009-1529 7.68.10.28742009-06-10
CVE-2020-35878 7.69.80.01522020-12-31
CVE-2020-35888 7.69.80.01522020-12-31
CVE-2021-26305 7.69.80.01692021-01-29
CVE-2021-26951 7.69.80.01732021-02-09
CVE-2021-29936 7.69.80.01332021-04-01